SMS Blaster: When the Scam Bypasses the Mobile Network Entirely and Comes from a Fake Antenna in a Car Boot

Back to the blog
4 September 202611 min read

For years, the fight against fraudulent text messages has rested on a simple assumption: a scam SMS has to travel through something. A sending platform, an aggregator, a carrier. And if a message goes through a pipe, it can be filtered, blocked, and traced back to its sender.

In 2026, that assumption is collapsing. A new generation of scams no longer uses any pipe at all. The message doesn't come from Orange, SFR, Bouygues or Free. It doesn't come from any carrier whatsoever. It is broadcast directly through the air, from a box sitting in the boot of a car driving past — or parked fifty metres away from you.

This is what's known as an SMS Blaster — sometimes called a "rogue base station", a "fake base station" or, in the older vocabulary of intelligence services, a cousin of the IMSI catcher. And the core problem is this: your carrier cannot filter a message it never saw go by.

Black and white photo of a hand holding a lit smartphone against a dark background

What an SMS Blaster actually is

A mobile phone is not a suspicious device. Its basic logic, inherited from the earliest GSM standards of the 1990s, is to connect to whichever antenna offers the strongest signal. It doesn't ask that antenna for any credentials. In the oldest network generations — 2G in particular — authentication runs one way only: the network verifies that your SIM card is legitimate, but your phone doesn't verify that the antenna is.

An SMS Blaster exploits precisely that design flaw. The kit fits in a sports bag or a hard-shell suitcase: a software-defined radio, an amplifier, a battery, sometimes just a laptop to drive the whole thing. It poses as a cell tower, forces nearby phones to drop off 4G or 5G and fall back to 2G, then injects an SMS straight into them.

The operating radius varies with power and surroundings — typically from a few dozen to a few hundred metres in a dense urban area. Moving slowly along a shopping street, an elevated metro line or a congested road, a single device can reach several thousand phones in an hour.

The crucial point: the SMS broadcast this way has no existence at all in the carrier's systems. It appears in no billing record, no monitoring platform, no anti-spam tool. As far as the network is concerned, that message was never sent.

Why the usual defences are useless here

French carriers have significantly beefed up their arsenal in recent years. The 33700 scheme, run by the Association Française du Multimédia Mobile, lets you report an unwanted SMS and get abusive numbers cut off. Network filters detect mass sending, blacklisted URLs and repetitive patterns. The MAN framework (Mécanisme d'Authentification des Numéros) has made caller ID spoofing far more difficult.

All of these mechanisms share one premise: the message travels through supervised infrastructure. The SMS Blaster blows that premise apart.

Conventional defenceEffectiveness against an SMS Blaster
Carrier anti-spam filteringNone — the message never crosses the network
Reporting to 33700Useful for the investigation, but there's no number to cut off
Blocking the sender's numberNone — the sender is an arbitrary label
Mass-sending detectionNone — no volume is visible on the carrier's side
Anti-spam app on the handsetPartial — depends on the content and the URL

Another, still more insidious consequence: the displayed sender is entirely chosen by the attacker. It can be a bank's name, a government agency's name, a well-known short code. On some phones, if the label exactly matches that of a legitimate sender already present in your conversations, the fraudulent message can slot itself into the existing message thread — right below the real texts from your bank or your pension fund. It is this sender-name grouping mechanism that explains certain recent waves of fake texts displaying the exact name of official bodies.

What these messages contain

The content isn't fundamentally different from ordinary smishing — it's the delivery method that changes. You'll find all the classics, written in impeccable French:

  • The held parcel: €1.79 in customs fees to be paid urgently, with a link to a cloned payment page.
  • The fake bank alert: "A €749 transaction has been initiated. If this wasn't you, click here."
  • The government angle: unpaid fine, health card update, insurance reimbursement, pension account correction.
  • The toll or parking notice: particularly effective when the blaster is travelling along a main road.
  • The fake verification code followed by a phone call: "Hello, this is your bank's fraud department, we're seeing an attempt on your account."

The emotional trigger is always the same: financial or administrative urgency, coupled with an action to be taken within twenty-four hours.

Why this technique has spread

Three factors have compounded each other.

The hardware has become affordable. Programmable software-defined radios, originally research and amateur-radio tools, now cost a few hundred euros. The know-how needed to repurpose them circulates in closed communities, packaged as ready-to-use kits.

The marginal cost is zero. Sending an SMS via a carrier costs money and leaves an accounting trail. Broadcasting a hundred thousand messages from a blaster costs nothing but electricity. That transforms the scam's business model: no more need for front accounts, SIM boxes or complicit aggregators.

Traceability is close to nil. The device has no subscription, no usable network identifier, no IP address. The only way to neutralise it is to locate it physically — radio direction-finding work that takes time, equipment and coordination between the ANFR (Agence nationale des fréquences), the carriers and law enforcement. Such operations do happen and do succeed, but they first require someone to report the anomaly.

Worth noting in passing: using such a device carries heavy criminal penalties in France — transmitting on allocated frequencies without authorisation, interfering with the operation of an electronic communications network, organised fraud. The sentences are counted in years of imprisonment.

The settings that genuinely make a difference

There's no "anti-SMS Blaster" button. But there is one measure whose effect is direct and measurable: turn off 2G.

Since the attack relies on forcing a downgrade to a protocol where the antenna doesn't have to prove its identity, a phone that flatly refuses 2G becomes far harder to trap.

On Android

Most recent versions of Android offer a dedicated toggle. The path varies by manufacturer, but it looks something like: Settings → Network & Internet → SIMs → select the SIM → "Allow 2G", to be switched off. Some manufacturers place the option under a "Security and privacy" menu.

On its most recent versions, Android also offers a network protection mode that refuses unencrypted connections and can warn you when the phone detects a base station behaving abnormally. If your device offers it, turn it on.

On iPhone

iOS has no standalone 2G toggle. It does, however, offer Lockdown Mode (Settings → Privacy & Security → Lockdown Mode), which among other things disables fallback to insecure cellular networks. It's a restrictive mode, designed for high-risk profiles — journalists, lawyers, elected officials — and it hampers some everyday uses. For most users it isn't recommended day to day, but it can be switched on occasionally in a risky setting.

The other settings worth having

  • Enable filtering of unknown senders (iOS: Settings → Apps → Messages; Android: Messages → Settings → Spam protection).
  • Always refuse to install apps from outside the App Store or Play Store. That's the main entry point for second-stage attacks.
  • Check that two-factor authentication on your sensitive accounts doesn't rely on SMS alone. An authenticator app — or better still, a physical FIDO2 security key — cuts the whole chain short: even with your credentials in hand, the attacker stays locked out.

A word on network coverage, incidentally: in areas where the 4G signal is weak, your phone naturally falls back to 2G — which makes you more vulnerable. If you live in a partial dead zone, an ARCEP-approved mobile signal repeater, properly installed, reduces that constant downgrading. A caveat: only approved and declared models are legal in France.

How to tell you've just been targeted

A few signals, individually unremarkable, add up to something:

  1. Your phone abruptly drops to 2G or "E" while you're in the middle of a city, in an area that's usually well covered.
  2. You lose signal for a few seconds, then a text arrives right after reconnection.
  3. The message appears nowhere in your carrier account history.
  4. Several people around you — in the same carriage, the same lobby, the same queue — receive the same message at the same moment.
  5. The displayed sender looks perfectly legitimate, but the link points to a domain slightly different from the official one.

That last point deserves a systematic reflex: never judge a text message by its displayed sender, always by the action it asks of you. A public body will never ask you for your full bank details by SMS. Ameli states this explicitly on its site: the Assurance Maladie never requests bank details or a social security number by message.

The right reflex, in three steps

Don't click. It sounds obvious, but it's the only breaking point that belongs entirely to you. An unread text does nothing. A read text does nothing. Only the click sets everything else in motion.

Verify through a channel you chose yourself. Not the number contained in the message, not the link: your banking app opened by hand, the number printed on the back of your card, the official website typed out yourself in the browser.

Report it. Forward the message to 33700 (free, all carriers) and, if you've suffered a loss, file a complaint through the dedicated online service. The Cybermalveillance.gouv.fr portal points you to the right contacts and offers clear step-by-step guides. Even without a usable sender, these reports feed the statistics that trigger ANFR's location-finding operations.

If the damage is done

The click has happened, the credentials have been entered. There's still a window for action, and it's short.

  • Block your card immediately with your bank, then through the interbank card-blocking service on 0 892 705 705.
  • Change the passwords on the affected accounts from another device — a computer, if you suspect the phone is compromised. A password manager also prevents the chain contamination of accounts sharing the same password.
  • Check your call forwarding and SMS forwarding rules. A common practice is to quietly enable forwarding in order to intercept verification codes.
  • Document everything: time-stamped screenshots of the message, the number, the time. These are the elements that will make the difference when filing a complaint and requesting a refund from your bank, a process governed by Articles L.133-18 and following of the French Monetary and Financial Code.

If you're helping a relative who's less comfortable with these reflexes, a practical guide to everyday cybersecurity, left on the living-room table, often does more work than a long lecture: it lets you come back to the subject several times without it feeling like a telling-off.

What will change in the coming years

The good news is that the technical vector is on its way out. 2G is officially being switched off by French carriers — Orange and SFR have set their shutdown timetables, and the others are following. The day no phone in circulation can fall back to 2G, this particular category of attack will lose most of its playing field.

The bad news is that researchers are already documenting variants targeting 4G, exploiting signalling messages that precede full authentication. The principle remains the same: between the moment a phone discovers an antenna and the moment it verifies that antenna's legitimacy, there is a window. It narrows with each generation, but it hasn't closed yet.

Until then, the reasoning to keep in mind is simple, and it holds well beyond the SMS Blaster: a message's apparent origin is never proof. Not the sender's name, not the thread it appears in, not the quality of the writing. All that matters is what the message asks you to do — and if that action involves your money, your credentials or your personal data, it deserves to be verified elsewhere, along a path you chose for yourself.

#SMS#Sécurité#smishing#fraude#Technique#Opérateurs#2026#Mobile#Conseil Sécurité#GSM

Related articles

Envoyez votre SMS gratuitement

Service 100% gratuit et sans inscription. Envoyez vos SMS vers la France en quelques secondes.

Envoyer un SMS